Vulnerability News

Microsoft Releases Emergency Patch For Windows Server Update Service RCE Vulnerability

Microsoft has rolled out an out-of-band emergency patch for a remote code execution (RCE) vulnerability affecting the Windows Server Update Services (WSUS).

Identified as CVE-2025-59287, the issue stems from the deserialization of untrusted data in a legacy serialization mechanism, allowing unauthorized attackers to execute arbitrary code over the network.

The patch, released on October 23, 2025, addresses the critical threat just days after the vulnerability’s initial disclosure on October 14.

Update: CISA Alerts of Hackers Actively Exploiting Windows Server Update Services RCE Vulnerability in the Wild

The flaw, rated critical with a CVSS 3.1 base score of 9.8, requires no user privileges or interaction, making it highly exploitable via the network with low complexity.

Attackers could send crafted events to trigger unsafe deserialization, potentially leading to full system compromise and severe impacts on confidentiality, integrity, and availability.

Vulnerability Exposes WSUS Servers To Remote Attacks

While WSUS is not enabled by default on Windows servers, thus sparing unmodified systems, organizations running the server role for update management face immediate risk if unpatched.

Microsoft’s security team updated the CVE’s temporal score to 8.8 after confirming the availability of proof-of-concept (PoC) exploit code, elevating the exploitability assessment to “more likely.”

No active exploitation in the wild has been reported yet, but the public disclosure of PoC code underscores the urgency for administrators to act.

The vulnerability was responsibly reported by researchers from MEOW and CODE WHITE GmbH, including Markus Wulftange, who identified the deserialization weakness tied to CWE-502.

The October 23 update is available through Windows Update, Microsoft Update, and the Microsoft Update Catalog for standalone downloads.

It will also sync automatically with WSUS environments. However, installation requires a server reboot, which could disrupt operations in production settings.

For those unable to patch immediately, Microsoft recommends temporary workarounds: disable the WSUS server role entirely, halting client updates in the process, or block inbound traffic to ports 8530 and 8531 at the host firewall level to neutralize the service.

This release highlights ongoing challenges in legacy components like WSUS, which many enterprises still rely on for centralized patch management.

Security experts urge organizations to review their WSUS configurations and prioritize the update to prevent potential breaches.

An updated Windows Update offline scan file (Wsusscn2.cab) is now available to aid detection. As cybersecurity threats evolve, this incident serves as a reminder of the importance of timely patching in enterprise environments. Microsoft continues to monitor for any emerging exploits.

Affected VersionPatch KB NumberNotes
Windows Server 2012KB5070887Standard and Server Core
Windows Server 2012 R2KB5070886Standard and Server Core
Windows Server 2016KB5070882Standard and Server Core
Windows Server 2019KB5070883Standard and Server Core
Windows Server 2022KB5070884Standard and Server Core
Windows Server 2022, 23H2 EditionKB5070879Server Core installation
Windows Server 2025KB5070881Standard and Server Core

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

16 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago